CVE-2007-3954
Microsoft Internet Explorer - Cross-Site Scripting via Mailto URI Shell Metacharacter Injection
Title source: llmDescription
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking SeaMonkey.exe, a related issue to CVE-2007-3670.
References (2)
Core 2
Core References
Various Sources x_refsource_misc
http://larholm.com/2007/07/23/seamonkey-suite-affected-by-url-vulnerability/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/25021
Scores
EPSS
0.0667
EPSS Percentile
93.2%
Details
CWE
CWE-79
Status
published
Products (2)
microsoft/internet_explorer
mozilla/seamonkey
Published
Jul 24, 2007
Tracked Since
Feb 18, 2026